Adultfriendfinder, other malware removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by czesklaj, Jul 2, 2006.

  1. czesklaj

    czesklaj Private E-2

    I'm sorry to be asking for help on this topic when I know that it has been asked before, but I've tried everything (including following directions/tips given to other users on the topic), and nothing has worked. I have completed every step from the "Read & Run Me First" page, and after 8+ hours of troubleshooting, I am still having pop-up problems. I have added the popup websites to my restricted sites list, so the websites still pop up, but they just don't load.

    The only problem I had when completing the "RRMF" page was that I was unable to access the internet in safe mode - therefore, I performed the Bitdefender and Panda ActiveScan tests in normal mode.

    I am running a Windows XP Home Edition V. 2002, SP2 with a Pentium(R) 4 CPU 3.00 GHz, 2.99 GHz, 2.00 GB of RAM.

    Any suggestions would be greatly appreciated!
    Abby
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please go back to step 7 of the READ ME and follow the directions exactly as written. You have installed HijackThis to one of the locations we indicated not to install it. Please do this first before you continue to the below.

    You also forgot to attach your CounterSpy log and why did you install CounterSpy like below?
    C:\Abby's Spyware Tools\sunserver.exe
    C:\Abby's Spyware Tools\SunProtectionServer.exe
    C:\Abby's Spyware Tools\sunThreatEngine.exe

    It is a bad practice to install programs to locations other than their recommended installation folders. They can look too much like malware themselves.

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of kbdilt.dll once and then click the kill button. After you have killed all of the kbdilt.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of kbdilt.dll and kill it. (If you do not find the dll, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    O2 - BHO: (no name) - {bb6b76e2-df7e-4b52-a6d7-a71f8113f522} - C:\WINDOWS\system32\kbdilt.dll
    O20 - Winlogon Notify: kbdilt - C:\WINDOWS\SYSTEM32\kbdilt.dll



    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command prompt window enter the below commands each followed by the Enter key.
    cd c:\windows\temp

    Now make sure the prompt (what you see at the beginning of each line in the command prompt window) shows that you are in the C:\windows\temp folder. Then continue.

    del win*.*
    exit

    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.
    C:\WINDOWS\SYSTEM32\kbdilt.dll

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now attach a new HJT log and tell me how the steps went.
    Make sure you tell me how things are working now!

    Also please now run the below procedure and attach the newfiles.txt log.

    Using ShowNew
     
  3. czesklaj

    czesklaj Private E-2

    Thanks for replying, Chaslang!

    The HJT log that was on my last post was an old one - I reread the directions and made a HJT folder under Program Files. Also, I no longer have CounterSpy on the computer (so I didn't attach the log) - I originally downloaded it because I was unable to download Windows Defender (even though I'm running XP/SP2).

    I followed your directions and the only problem I had was when I went to the c:\windows\temp folder and entered del win*.* it said that it could not be found. I have attached a new HJT log and the newfiles.txt log. It's hard for me to tell if the problem is fixed because the popups were so random to begin with.

    If I followed your directions under an account that has administrative priveleges, will I need to redo everything under the other account?

    I very much appreciate your help!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Were you unable to download it or were you unable to install it. This is not the samething? According to your HJT log it looks like it is already installed so I'm not sure what you really mean.

    I also still see CounterSpy installed??? So I guess you did not uninstall it after all?

    Maybe you need to uninstall CounterSPy and Windows Defender again and then reboot.

    Use PocketKillbox to delete the below file:
    C:\WINDOWS\SYSTEM32\geedefd.dll

    Are you having any malware problems?
     
  5. czesklaj

    czesklaj Private E-2

    Sorry to have caused confusion. I was able to download CounterSpy, and I thought I removed it from the computer because it doesn't show up under my Add/Remove Programs in the Control Panel.

    I have not had a problem with Windows Defender, but I will try removing and reinstalling it. The only program that alerted me to the "Trojan.Downloader.ConHook.R" in the kbdilt.dll file was Bitdefender (so I'm not sure how necessary Windows Defender is).

    I deleted the file and have attached new logs.

    No popups yet. :)

    Thank you!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Without Windows Defender, you will have no antispyware realtime protection installed. That would be a bad idea. Now ask youself why Symantec (with all the stuff they have installed on your PC) did not detect it!

    Use HijackThis to fix the below lines:
    O4 - HKLM\..\Run: [SunServer] C:\Abby's Spyware Tools\sunserver.exe
    O4 - HKLM\..\Run: [Windows Defender] "C:\Abby's Spyware Tools\MSASCui.exe" -hide

    Then delete those two files if they exist.

    Now install Windows Defender into it proper folder and make sure it work okay.


    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds